How 666bat Handles Your Personal Data
Your privacy matters to us, and this policy explains exactly what personal information 666bat collects when you open or use your account, how we store it securely, and...
What This Privacy Policy Covers and Why
This policy applies to all personal data you share with 666bat when you create an account, make a deposit via JazzCash, Easypaisa, SadaPay or Raast, or interact with our support team. We collect your name, contact details, payment references and device identifiers solely to operate your account and comply with applicable regulations in supported regions. We do not sell or rent your
information to marketing networks. Data submitted through Pakistani payment rails is handled under the same retention rules as all other account data, and we apply encryption at the point of entry. Where local law permits, you may request a full copy of the data we hold on your account by contacting our support team directly.
Service availability is jurisdiction-dependent. Users are responsible for checking local law before access.
Reach Us About Your Data Rights
If you have questions about this policy, want to update your stored information, or wish to submit a data deletion request, our support team handles privacy queries through three channels with response times measured in hours, not days.
Live Chat
Our live chat channel connects you to a privacy-aware support agent around the clock. Start a conversation from your account dashboard and reference 'data request' so your query is routed correctly within minutes.
Email Support
Send your privacy request to our dedicated support address. Include your registered account details and the specific action you want taken — correction, export or deletion — and we aim to respond within 24 hours.
Account Portal
Log into your 666bat account portal to review the personal details we currently hold, update your contact information directly, or submit a formal data access request without needing to contact an agent.
Six Practices That Keep Your Data Safe
We designed our data-handling practices around the reality that Pakistani account holders use mobile-first payment rails. Each of the following measures applies from the moment you submit your first JazzCash or Easypaisa...
TLS Encryption in Transit
Every data exchange between your device and 666bat servers travels over TLS 1.2 or higher. This covers account logins, payment submissions via JazzCash or Easypaisa, and any form you complete on the site.
Encrypted Storage at Rest
Personal details, KYC documents, and payment references stored on our servers are encrypted at rest using AES-256. Decryption keys are held separately and rotated on a defined schedule.
Access Logging
Every time your account is accessed — whether by you or by a support agent acting on a verified request — an access log entry is created. You can request your access log as part of a data export.
Payment Data Isolation
Transaction references from JazzCash, Easypaisa, SadaPay and Raast are stored in isolated tables with separate access controls, reducing the surface area for any single point of exposure.
Session Token Expiry
Active session tokens expire automatically after a defined period of inactivity. This limits the window during which an unattended device could expose your account to unauthorised access.
Staff Data Access Controls
Our team members access personal data only on a need-to-know basis tied to a specific support function. Access is logged, reviewed periodically, and revoked immediately when a role changes.
How This Policy Aligns With Our Other Terms
Our privacy commitments are consistent across every part of the 666bat platform. The table below shows how this policy connects to related documents so you can see the...
| Terms and Conditions | Our general terms define the account relationship; this privacy policy defines the data relationship. Both documents apply simultaneously when you hold an active 666bat account. |
|---|---|
| Cookie Policy | Our cookie policy covers browser and device identifiers specifically. This privacy policy covers all other personal data including payment details and KYC documents. |
| Withdrawal Terms | Withdrawal terms govern timing and method. This policy governs the personal data — including SadaPay and Raast identifiers — created during that withdrawal process. |
| Account Verification | KYC checks are described in account verification terms. This policy explains how the documents you submit during that process are stored, retained and eventually deleted. |
| Marketing Communications | If you opt into promotional communications, our email and SMS preferences page governs frequency. This policy explains what contact data we hold to deliver those communications. |
| Third-Party Integrations | Where we use third-party processors to route JazzCash or Easypaisa payments, those processors operate under data-processing agreements that require them to meet the same standards described here. |
| Data Retention Schedule | Our retention schedule sets the specific periods for each data category. This policy summarises those periods; the full schedule is available on request from our support team. |
Six Elements That Shape This Policy
Rather than a wall of legal text, we have structured this policy around six concrete commitments. Each one maps to a real aspect of how your...
Collection Scope
We collect only what we need to run your account — name, contact details, payment references and device identifiers. No speculative data collection, no profiling for third-party advertising, and no sharing without a lawful basis.
Storage Duration
Account data is held for the period your account is active plus the statutory retention period required under applicable local regulations. Once that window closes, data is deleted or anonymised on a documented schedule.
Your Access Rights
You may request a full export of the personal data we hold on you at any time. Requests are processed within the timeframe specified in this policy and fulfilled at no charge through your account portal or via email.
Correction and Deletion
If any detail we hold is inaccurate, you can correct it directly in your account portal. Deletion requests for data no longer required for legal or operational purposes are processed within 30 days of verification.
Security Architecture
Our privacy commitments are backed by technical controls — encryption, access logging and session management — described in the trust section of this policy. Commitments without controls are not commitments worth making.
Policy Update Process
When this policy changes materially, we notify account holders via the registered contact method before the change takes effect, giving you time to review the update before it applies to your account.